{
  "executive_summary": {
    "badge": "Unsafe",
    "security_score": 38.29,
    "view": "composite",
    "aggregate_verdict_withheld": false,
    "aggregate_verdict_withheld_reason": null,
    "scanner_badges": {
      "agentshield": "Verified",
      "cisco-skill-scanner": "Caution",
      "agent-audit-kit": "Unsafe",
      "bearer": "Unsafe",
      "nerlo-behavioral": "Verified",
      "nerlo-install-instruction": "Verified",
      "capslock": "not_applicable",
      "trivy": "Unsafe",
      "osv-scanner": "Unsafe",
      "trivy_image": "not_applicable",
      "govulncheck": "not_applicable"
    },
    "finding_counts": {
      "critical": 0,
      "high": 16,
      "medium": 30,
      "low": 4,
      "informational": 3
    },
    "recommendation": "2d-assets-mcp is NOT recommended for integration: the scan surfaced 0 critical and 16 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering."
  },
  "source_provenance": {
    "repository_url": "https://github.com/crony-io/2d-assets-mcp",
    "commit_sha_scanned": null,
    "license": "MIT",
    "maintainer": "Rafael Andrews",
    "name": "2d-assets-mcp",
    "version": "0.1.4"
  },
  "per_scanner_detail": [
    {
      "scanner_name": "agentshield",
      "scanner_version": "1.4.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 0.7102119940100238,
      "status": "complete",
      "examined": {
        "unit": "scan_targets",
        "count": 1
      },
      "metadata": {
        "source": "npm",
        "source_url": "https://www.npmjs.com/package/ecc-agentshield",
        "install_command": "npm install -g ecc-agentshield@1.4.0",
        "scans_performed": [
          "supply_chain"
        ]
      },
      "display_score": 100.0,
      "display_badge": "Verified"
    },
    {
      "scanner_name": "cisco-skill-scanner",
      "scanner_version": "2.0.11",
      "score": 66.5,
      "scanner_badge": "Caution",
      "findings": [
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo",
          "line_number": null,
          "rule_identifier": "LOW_ANALYZABILITY",
          "title": "Critically low analyzability score",
          "description": "[mcp_server policy: capability-matches-purpose class; severity high -> informational] Only 61% of skill content could be analyzed. 16 of 40 files are opaque to the scanner. The safety assessment has low confidence.",
          "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "social_engineering",
          "file_path": "/repo/SKILL.md",
          "line_number": null,
          "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
          "title": "Vague skill description",
          "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
          "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "medium",
          "category": "unicode_steganography",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": 0,
          "rule_identifier": "YARA_prompt_injection_unicode_steganography",
          "title": "UNICODE STEGANOGRAPHY detected by YARA",
          "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u202e",
          "remediation": "Review and remove unicode steganography pattern"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "medium",
          "category": "unicode_steganography",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": 0,
          "rule_identifier": "YARA_prompt_injection_unicode_steganography",
          "title": "UNICODE STEGANOGRAPHY detected by YARA",
          "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
          "remediation": "Review and remove unicode steganography pattern"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "medium",
          "category": "unicode_steganography",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": 0,
          "rule_identifier": "YARA_prompt_injection_unicode_steganography",
          "title": "UNICODE STEGANOGRAPHY detected by YARA",
          "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
          "remediation": "Review and remove unicode steganography pattern"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "medium",
          "category": "unicode_steganography",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": 0,
          "rule_identifier": "YARA_prompt_injection_unicode_steganography",
          "title": "UNICODE STEGANOGRAPHY detected by YARA",
          "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
          "remediation": "Review and remove unicode steganography pattern"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "medium",
          "category": "unicode_steganography",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": 0,
          "rule_identifier": "YARA_prompt_injection_unicode_steganography",
          "title": "UNICODE STEGANOGRAPHY detected by YARA",
          "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
          "remediation": "Review and remove unicode steganography pattern"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "medium",
          "category": "unicode_steganography",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": 0,
          "rule_identifier": "YARA_prompt_injection_unicode_steganography",
          "title": "UNICODE STEGANOGRAPHY detected by YARA",
          "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
          "remediation": "Review and remove unicode steganography pattern"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "policy_violation",
          "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
          "line_number": null,
          "rule_identifier": "OVERSIZED_FILE",
          "title": "Oversized file in skill package",
          "description": "File test_assets_mcp/readme_assets_display.gif is 9.0MB. Large files in skill packages may contain hidden content or serve as a vector for resource abuse.",
          "remediation": "Review large files and consider hosting externally."
        }
      ],
      "execution_duration_seconds": 8.290518836991396,
      "status": "complete",
      "examined": {
        "unit": "skills",
        "count": 1
      },
      "metadata": {
        "source": "pypi",
        "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
        "report_type": "cisco-skill-sast",
        "analyzers_used": [
          "bytecode",
          "pipeline",
          "static_analyzer"
        ],
        "skills_scanned": [
          "repo"
        ],
        "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
        "severity_counts": {
          "low": 1,
          "high": 0,
          "medium": 6,
          "critical": 0,
          "informational": 3
        },
        "artifact_type_policy": "mcp_server",
        "downweighted_findings": 2
      },
      "display_score": 66.5,
      "display_badge": "Caution"
    },
    {
      "scanner_name": "agent-audit-kit",
      "scanner_version": "0.3.26",
      "score": 55.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "mcp-config",
          "file_path": "src/server.ts",
          "line_number": 1,
          "rule_identifier": "AAK-MCP-018",
          "title": "Missing rate limiting on MCP endpoint",
          "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
          "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "mcp-config",
          "file_path": "src/tools/readMetadata.ts",
          "line_number": 3,
          "rule_identifier": "AAK-MCP-018",
          "title": "Missing rate limiting on MCP endpoint",
          "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
          "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "mcp-config",
          "file_path": "src/tools/generateBatch.ts",
          "line_number": 3,
          "rule_identifier": "AAK-MCP-018",
          "title": "Missing rate limiting on MCP endpoint",
          "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
          "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "mcp-config",
          "file_path": "src/tools/generateSingle.ts",
          "line_number": 1,
          "rule_identifier": "AAK-MCP-018",
          "title": "Missing rate limiting on MCP endpoint",
          "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
          "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "legal-compliance",
          "file_path": "CONTRIBUTING.md",
          "line_number": null,
          "rule_identifier": "AAK-HEALTHCARE-AI-004",
          "title": "Healthcare context without explicit AI-disclosure to user",
          "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
          "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": "package.json",
          "line_number": 61,
          "rule_identifier": "AAK-OAUTH-3P-001",
          "title": "Repo depends on a third-party agent-platform SDK",
          "description": "The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel \u00d7 Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants.",
          "remediation": "Pin the SDK to an exact version, audit the OAuth scopes it requests, and keep any deployment-level grants (Vercel, GCP, Workspace) in a secrets vault \u2014 never in a committed env file. See Vercel's bulletin for sensitive-env-var guidance: https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "high",
          "category": "supply-chain",
          "file_path": "src/index.ts",
          "line_number": null,
          "rule_identifier": "AAK-ANTHROPIC-SDK-001",
          "title": "MCP server built on the upstream SDK without STDIO sanitizer",
          "description": "Repository declares a dependency on the upstream Anthropic / ModelContextProtocol SDK (Python `mcp` / `modelcontextprotocol`, TS `@modelcontextprotocol/sdk`, Java `io.modelcontextprotocol:*`, Rust `mcp` / `modelcontextprotocol`) and exposes a STDIO transport (`StdioServerTransport`, `stdio_server`, etc.) without a sanitizer on argv assembly. Anthropic declined to CVE this as working as designed \u2014 sanitization is the developer's responsibility. The OX Security disclosure on 2026-04-15 rolled up L",
          "remediation": "Wrap every argv the STDIO transport builds in an allow-list sanitizer \u2014 `shlex.quote` in Python, `execFile` with an explicit argv array in Node, equivalent in Java/Rust. OR switch the transport off STDIO (`transports=['http']` / `['sse']`). If you have deliberately accepted the risk, add `accepts_stdio_risk: true` plus a `justification:` field in `.agent-audit-kit.yml`."
        }
      ],
      "execution_duration_seconds": 2.8152136970311403,
      "status": "complete",
      "examined": {
        "unit": "files",
        "count": 26
      },
      "metadata": {
        "source": "pypi",
        "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
        "report_type": "agent-audit-kit-sast",
        "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
        "rules_evaluated": 211,
        "severity_counts": {
          "low": 0,
          "high": 1,
          "medium": 6,
          "critical": 0,
          "informational": 0
        }
      },
      "display_score": 55.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "bearer",
      "scanner_version": "2.0.2",
      "score": 38.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "bearer",
          "severity": "high",
          "category": null,
          "file_path": "/repo/src/utils/string.ts",
          "line_number": 8,
          "rule_identifier": null,
          "title": "Usage of manual HTML sanitization (XSS)",
          "description": "## Description\n\nManually sanitizing HTML is prone to mistakes and can lead to Cross-Site Scripting (XSS) vulnerabilities. This occurs when user input is not properly sanitized, allowing attackers to inject malicious scripts into web pages viewed by other users.\n\n## Remediations\n\n- **Do not** manually escape HTML to sanitize user input. This method is unreliable and can easily miss certain exploits.\n  ```javascript\n  const sanitizedUserInput = user.Input\n    .replaceAll('<', '&lt;')\n    .replaceA",
          "remediation": null
        },
        {
          "tool_name": "bearer",
          "severity": "high",
          "category": null,
          "file_path": "/repo/src/tools/readMetadata.ts",
          "line_number": 28,
          "rule_identifier": null,
          "title": "Unsanitized dynamic input in file path",
          "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
          "remediation": null
        },
        {
          "tool_name": "bearer",
          "severity": "high",
          "category": null,
          "file_path": "/repo/src/utils/fs.ts",
          "line_number": 8,
          "rule_identifier": null,
          "title": "Unsanitized dynamic input in file path",
          "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
          "remediation": null
        },
        {
          "tool_name": "bearer",
          "severity": "high",
          "category": null,
          "file_path": "/repo/src/utils/fs.ts",
          "line_number": 9,
          "rule_identifier": null,
          "title": "Unsanitized dynamic input in file path",
          "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
          "remediation": null
        },
        {
          "tool_name": "bearer",
          "severity": "low",
          "category": null,
          "file_path": "/repo/src/index.ts",
          "line_number": 17,
          "rule_identifier": null,
          "title": "Leakage of information in logger message",
          "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
          "remediation": null
        }
      ],
      "execution_duration_seconds": 7.5220401210244745,
      "status": "complete",
      "examined": {
        "unit": "files",
        "count": 16
      },
      "metadata": {
        "source": "github-releases",
        "source_url": "https://github.com/Bearer/bearer",
        "report_type": "security",
        "rules_loaded": 554,
        "install_command": "curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /usr/local/bin \"v2.0.2\"",
        "severity_counts": {
          "low": 1,
          "high": 4,
          "medium": 0,
          "critical": 0,
          "informational": 0
        }
      },
      "display_score": 38.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "nerlo-behavioral",
      "scanner_version": "0.1.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 3.835563054017257,
      "status": "complete",
      "examined": {
        "unit": "files",
        "count": 16
      },
      "metadata": {
        "source": "nerlo-original",
        "source_url": "https://github.com/nerlo-ai/nerlo",
        "report_type": "nerlo-behavioral",
        "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
        "ruleset_paths": [
          "/opt/nerlo-rules/exfiltration.yaml",
          "/opt/nerlo-rules/clipboard_exfiltration.yaml",
          "/opt/nerlo-rules/rce_endpoint.yaml",
          "/opt/nerlo-rules/taint_egress.yaml"
        ],
        "install_command": "pip install 'semgrep==1.97.0'",
        "merged_invocation": true
      },
      "display_score": 100.0,
      "display_badge": "Verified"
    },
    {
      "scanner_name": "nerlo-install-instruction",
      "scanner_version": "0.1.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 3.836396912985947,
      "status": "complete",
      "examined": {
        "unit": "files",
        "count": 4
      },
      "metadata": {
        "source": "nerlo-original",
        "source_url": "https://github.com/nerlo-ai/nerlo",
        "report_type": "nerlo-install-instruction",
        "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
        "ruleset_paths": [
          "/opt/nerlo-rules/install_instructions.yaml",
          "/opt/nerlo-rules/cursor_rules.yaml"
        ],
        "install_command": "pip install 'semgrep==1.97.0'",
        "merged_invocation": true
      },
      "display_score": 100.0,
      "display_badge": "Verified"
    },
    {
      "scanner_name": "capslock",
      "scanner_version": "v0.3.2",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 0.1310226009809412,
      "status": "not_applicable",
      "examined": {
        "unit": "packages",
        "count": 0
      },
      "metadata": {
        "source": "go-module-proxy",
        "source_url": "https://github.com/google/capslock/releases/tag/v0.3.2",
        "report_type": "go-capability",
        "vendor_mode": false,
        "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install github.com/google/capslock/cmd/capslock@v0.3.2  # github.com/google/capslock v0.3.2 h1:0ZQa9YR8s9ewFu1g5w6Rgd/lW/4dga7qJew3K6Ql7aM=",
        "environment_note": "capslock found no .go files to analyze; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute",
        "go_files_present": 0,
        "artifact_type_policy": "mcp_server",
        "expected_capabilities": [
          "CAPABILITY_FILES",
          "CAPABILITY_NETWORK",
          "CAPABILITY_READ_SYSTEM_STATE",
          "CAPABILITY_REFLECT",
          "CAPABILITY_RUNTIME"
        ],
        "artifact_type_explicit": true
      },
      "display_score": null,
      "display_badge": "not_applicable"
    },
    {
      "scanner_name": "trivy",
      "scanner_version": "0.71.0",
      "score": 0.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-frvp-7c67-39w9",
          "title": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
          "description": "The same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t",
          "remediation": "Upgrade @hono/node-server from 1.19.14 to 2.0.5 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-13676",
          "title": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization",
          "description": "fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo",
          "remediation": "Upgrade fast-uri from 3.1.2 to 4.0.1, 3.1.3, 2.4.2 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-16221",
          "title": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...",
          "description": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f",
          "remediation": "Upgrade fast-uri from 3.1.2 to 2.4.3, 3.1.4, 4.1.1 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-18446",
          "title": "fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority",
          "description": "fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applicati",
          "remediation": "Upgrade fast-uri from 3.1.2 to 2.4.4, 3.1.5, 4.1.2 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-59895",
          "title": "hono: Hono: Arbitrary markup injection via improper handling of class names in server-side rendering.",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-59896",
          "title": "hono: Hono: Information disclosure due to improper context isolation in server-side rendering",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-59897",
          "title": "hono: Hono: Information disclosure due to incorrect header de-duplication in AWS API Gateway v1 adapter",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-69207",
          "title": "Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-Control-Request-Headers header using a whitespace-tolerant regular expression whose backtracking makes its running time quadratic in the input length. Because the header value is bounded only by the de",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-71848",
          "title": "Hono: Algorithmic Complexity DoS in Language Middleware",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separated subtags. To implement progressive language tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join('-') for every possible prefix, so the total amount of string processing grows quadratically wit",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-71850",
          "title": "Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and request scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request. Components wrapped with memo() are compared by props alone; values read implicitly during rendering, such as JSX ",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-71849",
          "title": "Hono: Proxy Helper does not remove response headers listed in the `Connection` header",
          "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message's Connection header field before forwarding the message, in addition to the well known hop by hop headers, but the proxy() function only removed the well known hop by hop head",
          "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-69192",
          "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
          "description": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects t",
          "remediation": "Upgrade ip-address from 10.2.0 to 10.3.1 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-54272",
          "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
          "description": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 address",
          "remediation": "Upgrade ip-address from 10.2.0 to 10.2.1 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "pnpm",
          "file_path": "pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "CVE-2026-69198",
          "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
          "description": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), i",
          "remediation": "Upgrade ip-address from 10.2.0 to 10.2.2 or later"
        }
      ],
      "execution_duration_seconds": 0.22111369797494262,
      "status": "complete",
      "examined": {
        "unit": "manifests",
        "count": 1
      },
      "metadata": {
        "source": "github-releases",
        "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
        "report_type": "filesystem-vulnerability",
        "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
        "severity_counts": {
          "low": 1,
          "high": 4,
          "medium": 9,
          "critical": 0,
          "informational": 0
        },
        "manifests_scanned": [
          "pnpm-lock.yaml"
        ]
      },
      "display_score": 0.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "osv-scanner",
      "scanner_version": "2.3.8",
      "score": 0.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-frvp-7c67-39w9",
          "title": "GHSA-frvp-7c67-39w9 \u2014 npm @hono/node-server@1.19.14",
          "description": "aliases: GHSA-frvp-7c67-39w9 | CVSS: 5.9",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-3jxr-9vmj-r5cp",
          "title": "GHSA-3jxr-9vmj-r5cp \u2014 npm brace-expansion@5.0.6",
          "description": "aliases: CVE-2026-13149, GHSA-3jxr-9vmj-r5cp | CVSS: 7.7",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-mh99-v99m-4gvg",
          "title": "GHSA-mh99-v99m-4gvg \u2014 npm brace-expansion@5.0.6",
          "description": "aliases: CVE-2026-14257, GHSA-mh99-v99m-4gvg | CVSS: 7.5",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-rgw5-rvv9-x895",
          "title": "GHSA-rgw5-rvv9-x895 \u2014 npm brace-expansion@5.0.6",
          "description": "aliases: CVE-2026-69152, GHSA-rgw5-rvv9-x895 | CVSS: 7.5",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-4c8g-83qw-93j6",
          "title": "GHSA-4c8g-83qw-93j6 \u2014 npm fast-uri@3.1.2",
          "description": "aliases: CVE-2026-13676, GHSA-4c8g-83qw-93j6 | CVSS: 7.5",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-7p8r-x3mc-p8w7",
          "title": "GHSA-7p8r-x3mc-p8w7 \u2014 npm fast-uri@3.1.2",
          "description": "aliases: CVE-2026-18446, GHSA-7p8r-x3mc-p8w7 | CVSS: 7.5",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-v2hh-gcrm-f6hx",
          "title": "GHSA-v2hh-gcrm-f6hx \u2014 npm fast-uri@3.1.2",
          "description": "aliases: CVE-2026-16221, GHSA-v2hh-gcrm-f6hx | CVSS: 7.5",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-54fx-42gc-7vw4",
          "title": "GHSA-54fx-42gc-7vw4 \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-71848, GHSA-54fx-42gc-7vw4 | CVSS: 5.3",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "low",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-79qm-7rj5-m7r9",
          "title": "GHSA-79qm-7rj5-m7r9 \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-71849, GHSA-79qm-7rj5-m7r9 | CVSS: 3.7",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-8j4g-w8fx-2239",
          "title": "GHSA-8j4g-w8fx-2239 \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-69207, GHSA-8j4g-w8fx-2239 | CVSS: 5.3",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-f23p-vx2j-j53r",
          "title": "GHSA-f23p-vx2j-j53r \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-71850, GHSA-f23p-vx2j-j53r | CVSS: 4.8",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-hvrm-45r6-mjfj",
          "title": "GHSA-hvrm-45r6-mjfj \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-59896, GHSA-hvrm-45r6-mjfj | CVSS: 6.5",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-w62v-xxxg-mg59",
          "title": "GHSA-w62v-xxxg-mg59 \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-59895, GHSA-w62v-xxxg-mg59 | CVSS: 6.1",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-xgm2-5f3f-mvvc",
          "title": "GHSA-xgm2-5f3f-mvvc \u2014 npm hono@4.12.25",
          "description": "aliases: CVE-2026-59897, GHSA-xgm2-5f3f-mvvc | CVSS: 4.8",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-22jq-vg5j-6vgg",
          "title": "GHSA-22jq-vg5j-6vgg \u2014 npm ip-address@10.2.0",
          "description": "aliases: CVE-2026-54272, GHSA-22jq-vg5j-6vgg | CVSS: 6.9",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "medium",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-4xrf-jv44-h6hh",
          "title": "GHSA-4xrf-jv44-h6hh \u2014 npm ip-address@10.2.0",
          "description": "aliases: CVE-2026-69198, GHSA-4xrf-jv44-h6hh | CVSS: 6.9",
          "remediation": null
        },
        {
          "tool_name": "osv-scanner",
          "severity": "high",
          "category": "npm",
          "file_path": "/repo/pnpm-lock.yaml",
          "line_number": null,
          "rule_identifier": "GHSA-mwp4-54f8-5fhr",
          "title": "GHSA-mwp4-54f8-5fhr \u2014 npm ip-address@10.2.0",
          "description": "aliases: CVE-2026-69192, GHSA-mwp4-54f8-5fhr | CVSS: 7.7",
          "remediation": null
        }
      ],
      "execution_duration_seconds": 6.83172498102067,
      "status": "complete",
      "examined": {
        "unit": "manifests",
        "count": 1
      },
      "metadata": {
        "source": "github-releases",
        "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
        "report_type": "osv-vulnerability",
        "ecosystems_seen": [
          "npm"
        ],
        "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
        "severity_counts": {
          "low": 1,
          "high": 7,
          "medium": 9,
          "critical": 0,
          "informational": 0
        },
        "manifests_scanned": [
          "/repo/pnpm-lock.yaml"
        ],
        "finding_id_aliases": {
          "GHSA-22jq-vg5j-6vgg": [
            "CVE-2026-54272"
          ],
          "GHSA-3jxr-9vmj-r5cp": [
            "CVE-2026-13149"
          ],
          "GHSA-4c8g-83qw-93j6": [
            "CVE-2026-13676"
          ],
          "GHSA-4xrf-jv44-h6hh": [
            "CVE-2026-69198"
          ],
          "GHSA-54fx-42gc-7vw4": [
            "CVE-2026-71848"
          ],
          "GHSA-79qm-7rj5-m7r9": [
            "CVE-2026-71849"
          ],
          "GHSA-7p8r-x3mc-p8w7": [
            "CVE-2026-18446"
          ],
          "GHSA-8j4g-w8fx-2239": [
            "CVE-2026-69207"
          ],
          "GHSA-f23p-vx2j-j53r": [
            "CVE-2026-71850"
          ],
          "GHSA-hvrm-45r6-mjfj": [
            "CVE-2026-59896"
          ],
          "GHSA-mh99-v99m-4gvg": [
            "CVE-2026-14257"
          ],
          "GHSA-mwp4-54f8-5fhr": [
            "CVE-2026-69192"
          ],
          "GHSA-rgw5-rvv9-x895": [
            "CVE-2026-69152"
          ],
          "GHSA-v2hh-gcrm-f6hx": [
            "CVE-2026-16221"
          ],
          "GHSA-w62v-xxxg-mg59": [
            "CVE-2026-59895"
          ],
          "GHSA-xgm2-5f3f-mvvc": [
            "CVE-2026-59897"
          ]
        },
        "cross_scanner_correlation": {
          "only_osv": [
            "GHSA-3jxr-9vmj-r5cp",
            "GHSA-mh99-v99m-4gvg",
            "GHSA-rgw5-rvv9-x895"
          ],
          "only_trivy": [],
          "intersection_ids": [
            "CVE-2026-13676",
            "CVE-2026-16221",
            "CVE-2026-18446",
            "CVE-2026-54272",
            "CVE-2026-59895",
            "CVE-2026-59896",
            "CVE-2026-59897",
            "CVE-2026-69192",
            "CVE-2026-69198",
            "CVE-2026-69207",
            "CVE-2026-71848",
            "CVE-2026-71849",
            "CVE-2026-71850",
            "GHSA-frvp-7c67-39w9"
          ]
        }
      },
      "display_score": 0.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "trivy_image",
      "scanner_version": "0.71.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 3.597000613808632e-05,
      "status": "not_applicable",
      "examined": {
        "unit": "image_targets",
        "count": 0
      },
      "metadata": {
        "reason": "no OCI image acquired for this artifact"
      },
      "display_score": null,
      "display_badge": "not_applicable"
    },
    {
      "scanner_name": "govulncheck",
      "scanner_version": "v1.6.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 0.06348048703512177,
      "status": "not_applicable",
      "examined": {
        "unit": "modules",
        "count": 0
      },
      "metadata": {
        "source": "go-module-proxy",
        "source_url": "https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck",
        "report_type": "go-reachability",
        "vendor_mode": false,
        "go_mod_present": false,
        "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install golang.org/x/vuln/cmd/govulncheck@v1.6.0  # golang.org/x/vuln v1.6.0 h1:FeMO9Rm/HwyduOztbvKcOw+zvDEPr4I4aQNSfevFcKY=",
        "offline_db_path": "/opt/govulncheck-db",
        "environment_note": "govulncheck found no go.mod, so this tree declares no Go module and no Go dependencies; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute"
      },
      "display_score": null,
      "display_badge": "not_applicable"
    }
  ],
  "threat_model": "Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.",
  "audit_chain": {
    "scan_job_id": "d418bde1-ea1d-4bcb-b93b-305f9ae12571",
    "scan_completed_at": "2026-08-12T13:32:17.926283+00:00",
    "scanner_versions": {
      "agentshield": "1.4.0",
      "cisco-skill-scanner": "2.0.11",
      "agent-audit-kit": "0.3.26",
      "bearer": "2.0.2",
      "nerlo-behavioral": "0.1.0",
      "nerlo-install-instruction": "0.1.0",
      "capslock": "v0.3.2",
      "trivy": "0.71.0",
      "osv-scanner": "2.3.8",
      "trivy_image": "0.71.0",
      "govulncheck": "v1.6.0"
    },
    "scanner_base_image": "us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:d5aaefa8b517d1f03832091ab094e20dc73160a07ae1102af1b2e395ce6ce852",
    "ai_decision_log_ids": [
      "09b8f73d-014a-45b5-a411-a95e7834740b",
      "171d807a-36d7-468a-afb6-211cbfb5f2f2"
    ],
    "self_attestation_url": "http://localhost:8000/api/v1/registry/self-attestation"
  },
  "appendix": {
    "raw_scanner_reports": [
      {
        "scanner_name": "agentshield",
        "scanner_version": "1.4.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 0.7102119940100238,
        "status": "complete",
        "examined": {
          "unit": "scan_targets",
          "count": 1
        },
        "metadata": {
          "source": "npm",
          "source_url": "https://www.npmjs.com/package/ecc-agentshield",
          "install_command": "npm install -g ecc-agentshield@1.4.0",
          "scans_performed": [
            "supply_chain"
          ]
        },
        "display_score": 100.0,
        "display_badge": "Verified"
      },
      {
        "scanner_name": "cisco-skill-scanner",
        "scanner_version": "2.0.11",
        "score": 66.5,
        "scanner_badge": "Caution",
        "findings": [
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo",
            "line_number": null,
            "rule_identifier": "LOW_ANALYZABILITY",
            "title": "Critically low analyzability score",
            "description": "[mcp_server policy: capability-matches-purpose class; severity high -> informational] Only 61% of skill content could be analyzed. 16 of 40 files are opaque to the scanner. The safety assessment has low confidence.",
            "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "social_engineering",
            "file_path": "/repo/SKILL.md",
            "line_number": null,
            "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
            "title": "Vague skill description",
            "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
            "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "medium",
            "category": "unicode_steganography",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": 0,
            "rule_identifier": "YARA_prompt_injection_unicode_steganography",
            "title": "UNICODE STEGANOGRAPHY detected by YARA",
            "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u202e",
            "remediation": "Review and remove unicode steganography pattern"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "medium",
            "category": "unicode_steganography",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": 0,
            "rule_identifier": "YARA_prompt_injection_unicode_steganography",
            "title": "UNICODE STEGANOGRAPHY detected by YARA",
            "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
            "remediation": "Review and remove unicode steganography pattern"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "medium",
            "category": "unicode_steganography",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": 0,
            "rule_identifier": "YARA_prompt_injection_unicode_steganography",
            "title": "UNICODE STEGANOGRAPHY detected by YARA",
            "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
            "remediation": "Review and remove unicode steganography pattern"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "medium",
            "category": "unicode_steganography",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": 0,
            "rule_identifier": "YARA_prompt_injection_unicode_steganography",
            "title": "UNICODE STEGANOGRAPHY detected by YARA",
            "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
            "remediation": "Review and remove unicode steganography pattern"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "medium",
            "category": "unicode_steganography",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": 0,
            "rule_identifier": "YARA_prompt_injection_unicode_steganography",
            "title": "UNICODE STEGANOGRAPHY detected by YARA",
            "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
            "remediation": "Review and remove unicode steganography pattern"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "medium",
            "category": "unicode_steganography",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": 0,
            "rule_identifier": "YARA_prompt_injection_unicode_steganography",
            "title": "UNICODE STEGANOGRAPHY detected by YARA",
            "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
            "remediation": "Review and remove unicode steganography pattern"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "policy_violation",
            "file_path": "/repo/test_assets_mcp/readme_assets_display.gif",
            "line_number": null,
            "rule_identifier": "OVERSIZED_FILE",
            "title": "Oversized file in skill package",
            "description": "File test_assets_mcp/readme_assets_display.gif is 9.0MB. Large files in skill packages may contain hidden content or serve as a vector for resource abuse.",
            "remediation": "Review large files and consider hosting externally."
          }
        ],
        "execution_duration_seconds": 8.290518836991396,
        "status": "complete",
        "examined": {
          "unit": "skills",
          "count": 1
        },
        "metadata": {
          "source": "pypi",
          "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
          "report_type": "cisco-skill-sast",
          "analyzers_used": [
            "bytecode",
            "pipeline",
            "static_analyzer"
          ],
          "skills_scanned": [
            "repo"
          ],
          "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
          "severity_counts": {
            "low": 1,
            "high": 0,
            "medium": 6,
            "critical": 0,
            "informational": 3
          },
          "artifact_type_policy": "mcp_server",
          "downweighted_findings": 2
        },
        "display_score": 66.5,
        "display_badge": "Caution"
      },
      {
        "scanner_name": "agent-audit-kit",
        "scanner_version": "0.3.26",
        "score": 55.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "mcp-config",
            "file_path": "src/server.ts",
            "line_number": 1,
            "rule_identifier": "AAK-MCP-018",
            "title": "Missing rate limiting on MCP endpoint",
            "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
            "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "mcp-config",
            "file_path": "src/tools/readMetadata.ts",
            "line_number": 3,
            "rule_identifier": "AAK-MCP-018",
            "title": "Missing rate limiting on MCP endpoint",
            "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
            "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "mcp-config",
            "file_path": "src/tools/generateBatch.ts",
            "line_number": 3,
            "rule_identifier": "AAK-MCP-018",
            "title": "Missing rate limiting on MCP endpoint",
            "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
            "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "mcp-config",
            "file_path": "src/tools/generateSingle.ts",
            "line_number": 1,
            "rule_identifier": "AAK-MCP-018",
            "title": "Missing rate limiting on MCP endpoint",
            "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
            "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "legal-compliance",
            "file_path": "CONTRIBUTING.md",
            "line_number": null,
            "rule_identifier": "AAK-HEALTHCARE-AI-004",
            "title": "Healthcare context without explicit AI-disclosure to user",
            "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
            "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": "package.json",
            "line_number": 61,
            "rule_identifier": "AAK-OAUTH-3P-001",
            "title": "Repo depends on a third-party agent-platform SDK",
            "description": "The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel \u00d7 Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants.",
            "remediation": "Pin the SDK to an exact version, audit the OAuth scopes it requests, and keep any deployment-level grants (Vercel, GCP, Workspace) in a secrets vault \u2014 never in a committed env file. See Vercel's bulletin for sensitive-env-var guidance: https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "high",
            "category": "supply-chain",
            "file_path": "src/index.ts",
            "line_number": null,
            "rule_identifier": "AAK-ANTHROPIC-SDK-001",
            "title": "MCP server built on the upstream SDK without STDIO sanitizer",
            "description": "Repository declares a dependency on the upstream Anthropic / ModelContextProtocol SDK (Python `mcp` / `modelcontextprotocol`, TS `@modelcontextprotocol/sdk`, Java `io.modelcontextprotocol:*`, Rust `mcp` / `modelcontextprotocol`) and exposes a STDIO transport (`StdioServerTransport`, `stdio_server`, etc.) without a sanitizer on argv assembly. Anthropic declined to CVE this as working as designed \u2014 sanitization is the developer's responsibility. The OX Security disclosure on 2026-04-15 rolled up L",
            "remediation": "Wrap every argv the STDIO transport builds in an allow-list sanitizer \u2014 `shlex.quote` in Python, `execFile` with an explicit argv array in Node, equivalent in Java/Rust. OR switch the transport off STDIO (`transports=['http']` / `['sse']`). If you have deliberately accepted the risk, add `accepts_stdio_risk: true` plus a `justification:` field in `.agent-audit-kit.yml`."
          }
        ],
        "execution_duration_seconds": 2.8152136970311403,
        "status": "complete",
        "examined": {
          "unit": "files",
          "count": 26
        },
        "metadata": {
          "source": "pypi",
          "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
          "report_type": "agent-audit-kit-sast",
          "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
          "rules_evaluated": 211,
          "severity_counts": {
            "low": 0,
            "high": 1,
            "medium": 6,
            "critical": 0,
            "informational": 0
          }
        },
        "display_score": 55.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "bearer",
        "scanner_version": "2.0.2",
        "score": 38.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "bearer",
            "severity": "high",
            "category": null,
            "file_path": "/repo/src/utils/string.ts",
            "line_number": 8,
            "rule_identifier": null,
            "title": "Usage of manual HTML sanitization (XSS)",
            "description": "## Description\n\nManually sanitizing HTML is prone to mistakes and can lead to Cross-Site Scripting (XSS) vulnerabilities. This occurs when user input is not properly sanitized, allowing attackers to inject malicious scripts into web pages viewed by other users.\n\n## Remediations\n\n- **Do not** manually escape HTML to sanitize user input. This method is unreliable and can easily miss certain exploits.\n  ```javascript\n  const sanitizedUserInput = user.Input\n    .replaceAll('<', '&lt;')\n    .replaceA",
            "remediation": null
          },
          {
            "tool_name": "bearer",
            "severity": "high",
            "category": null,
            "file_path": "/repo/src/tools/readMetadata.ts",
            "line_number": 28,
            "rule_identifier": null,
            "title": "Unsanitized dynamic input in file path",
            "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
            "remediation": null
          },
          {
            "tool_name": "bearer",
            "severity": "high",
            "category": null,
            "file_path": "/repo/src/utils/fs.ts",
            "line_number": 8,
            "rule_identifier": null,
            "title": "Unsanitized dynamic input in file path",
            "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
            "remediation": null
          },
          {
            "tool_name": "bearer",
            "severity": "high",
            "category": null,
            "file_path": "/repo/src/utils/fs.ts",
            "line_number": 9,
            "rule_identifier": null,
            "title": "Unsanitized dynamic input in file path",
            "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
            "remediation": null
          },
          {
            "tool_name": "bearer",
            "severity": "low",
            "category": null,
            "file_path": "/repo/src/index.ts",
            "line_number": 17,
            "rule_identifier": null,
            "title": "Leakage of information in logger message",
            "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
            "remediation": null
          }
        ],
        "execution_duration_seconds": 7.5220401210244745,
        "status": "complete",
        "examined": {
          "unit": "files",
          "count": 16
        },
        "metadata": {
          "source": "github-releases",
          "source_url": "https://github.com/Bearer/bearer",
          "report_type": "security",
          "rules_loaded": 554,
          "install_command": "curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /usr/local/bin \"v2.0.2\"",
          "severity_counts": {
            "low": 1,
            "high": 4,
            "medium": 0,
            "critical": 0,
            "informational": 0
          }
        },
        "display_score": 38.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "nerlo-behavioral",
        "scanner_version": "0.1.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 3.835563054017257,
        "status": "complete",
        "examined": {
          "unit": "files",
          "count": 16
        },
        "metadata": {
          "source": "nerlo-original",
          "source_url": "https://github.com/nerlo-ai/nerlo",
          "report_type": "nerlo-behavioral",
          "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
          "ruleset_paths": [
            "/opt/nerlo-rules/exfiltration.yaml",
            "/opt/nerlo-rules/clipboard_exfiltration.yaml",
            "/opt/nerlo-rules/rce_endpoint.yaml",
            "/opt/nerlo-rules/taint_egress.yaml"
          ],
          "install_command": "pip install 'semgrep==1.97.0'",
          "merged_invocation": true
        },
        "display_score": 100.0,
        "display_badge": "Verified"
      },
      {
        "scanner_name": "nerlo-install-instruction",
        "scanner_version": "0.1.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 3.836396912985947,
        "status": "complete",
        "examined": {
          "unit": "files",
          "count": 4
        },
        "metadata": {
          "source": "nerlo-original",
          "source_url": "https://github.com/nerlo-ai/nerlo",
          "report_type": "nerlo-install-instruction",
          "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
          "ruleset_paths": [
            "/opt/nerlo-rules/install_instructions.yaml",
            "/opt/nerlo-rules/cursor_rules.yaml"
          ],
          "install_command": "pip install 'semgrep==1.97.0'",
          "merged_invocation": true
        },
        "display_score": 100.0,
        "display_badge": "Verified"
      },
      {
        "scanner_name": "capslock",
        "scanner_version": "v0.3.2",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 0.1310226009809412,
        "status": "not_applicable",
        "examined": {
          "unit": "packages",
          "count": 0
        },
        "metadata": {
          "source": "go-module-proxy",
          "source_url": "https://github.com/google/capslock/releases/tag/v0.3.2",
          "report_type": "go-capability",
          "vendor_mode": false,
          "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install github.com/google/capslock/cmd/capslock@v0.3.2  # github.com/google/capslock v0.3.2 h1:0ZQa9YR8s9ewFu1g5w6Rgd/lW/4dga7qJew3K6Ql7aM=",
          "environment_note": "capslock found no .go files to analyze; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute",
          "go_files_present": 0,
          "artifact_type_policy": "mcp_server",
          "expected_capabilities": [
            "CAPABILITY_FILES",
            "CAPABILITY_NETWORK",
            "CAPABILITY_READ_SYSTEM_STATE",
            "CAPABILITY_REFLECT",
            "CAPABILITY_RUNTIME"
          ],
          "artifact_type_explicit": true
        },
        "display_score": null,
        "display_badge": "not_applicable"
      },
      {
        "scanner_name": "trivy",
        "scanner_version": "0.71.0",
        "score": 0.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-frvp-7c67-39w9",
            "title": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
            "description": "The same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t",
            "remediation": "Upgrade @hono/node-server from 1.19.14 to 2.0.5 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-13676",
            "title": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization",
            "description": "fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo",
            "remediation": "Upgrade fast-uri from 3.1.2 to 4.0.1, 3.1.3, 2.4.2 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-16221",
            "title": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...",
            "description": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f",
            "remediation": "Upgrade fast-uri from 3.1.2 to 2.4.3, 3.1.4, 4.1.1 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-18446",
            "title": "fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority",
            "description": "fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applicati",
            "remediation": "Upgrade fast-uri from 3.1.2 to 2.4.4, 3.1.5, 4.1.2 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-59895",
            "title": "hono: Hono: Arbitrary markup injection via improper handling of class names in server-side rendering.",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-59896",
            "title": "hono: Hono: Information disclosure due to improper context isolation in server-side rendering",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-59897",
            "title": "hono: Hono: Information disclosure due to incorrect header de-duplication in AWS API Gateway v1 adapter",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.27 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-69207",
            "title": "Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-Control-Request-Headers header using a whitespace-tolerant regular expression whose backtracking makes its running time quadratic in the input length. Because the header value is bounded only by the de",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-71848",
            "title": "Hono: Algorithmic Complexity DoS in Language Middleware",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separated subtags. To implement progressive language tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join('-') for every possible prefix, so the total amount of string processing grows quadratically wit",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-71850",
            "title": "Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and request scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request. Components wrapped with memo() are compared by props alone; values read implicitly during rendering, such as JSX ",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-71849",
            "title": "Hono: Proxy Helper does not remove response headers listed in the `Connection` header",
            "description": "Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message's Connection header field before forwarding the message, in addition to the well known hop by hop headers, but the proxy() function only removed the well known hop by hop head",
            "remediation": "Upgrade hono from 4.12.25 to 4.12.34 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-69192",
            "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "description": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects t",
            "remediation": "Upgrade ip-address from 10.2.0 to 10.3.1 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-54272",
            "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
            "description": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 address",
            "remediation": "Upgrade ip-address from 10.2.0 to 10.2.1 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "pnpm",
            "file_path": "pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "CVE-2026-69198",
            "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "description": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), i",
            "remediation": "Upgrade ip-address from 10.2.0 to 10.2.2 or later"
          }
        ],
        "execution_duration_seconds": 0.22111369797494262,
        "status": "complete",
        "examined": {
          "unit": "manifests",
          "count": 1
        },
        "metadata": {
          "source": "github-releases",
          "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
          "report_type": "filesystem-vulnerability",
          "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
          "severity_counts": {
            "low": 1,
            "high": 4,
            "medium": 9,
            "critical": 0,
            "informational": 0
          },
          "manifests_scanned": [
            "pnpm-lock.yaml"
          ]
        },
        "display_score": 0.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "osv-scanner",
        "scanner_version": "2.3.8",
        "score": 0.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-frvp-7c67-39w9",
            "title": "GHSA-frvp-7c67-39w9 \u2014 npm @hono/node-server@1.19.14",
            "description": "aliases: GHSA-frvp-7c67-39w9 | CVSS: 5.9",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-3jxr-9vmj-r5cp",
            "title": "GHSA-3jxr-9vmj-r5cp \u2014 npm brace-expansion@5.0.6",
            "description": "aliases: CVE-2026-13149, GHSA-3jxr-9vmj-r5cp | CVSS: 7.7",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-mh99-v99m-4gvg",
            "title": "GHSA-mh99-v99m-4gvg \u2014 npm brace-expansion@5.0.6",
            "description": "aliases: CVE-2026-14257, GHSA-mh99-v99m-4gvg | CVSS: 7.5",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-rgw5-rvv9-x895",
            "title": "GHSA-rgw5-rvv9-x895 \u2014 npm brace-expansion@5.0.6",
            "description": "aliases: CVE-2026-69152, GHSA-rgw5-rvv9-x895 | CVSS: 7.5",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-4c8g-83qw-93j6",
            "title": "GHSA-4c8g-83qw-93j6 \u2014 npm fast-uri@3.1.2",
            "description": "aliases: CVE-2026-13676, GHSA-4c8g-83qw-93j6 | CVSS: 7.5",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-7p8r-x3mc-p8w7",
            "title": "GHSA-7p8r-x3mc-p8w7 \u2014 npm fast-uri@3.1.2",
            "description": "aliases: CVE-2026-18446, GHSA-7p8r-x3mc-p8w7 | CVSS: 7.5",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-v2hh-gcrm-f6hx",
            "title": "GHSA-v2hh-gcrm-f6hx \u2014 npm fast-uri@3.1.2",
            "description": "aliases: CVE-2026-16221, GHSA-v2hh-gcrm-f6hx | CVSS: 7.5",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-54fx-42gc-7vw4",
            "title": "GHSA-54fx-42gc-7vw4 \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-71848, GHSA-54fx-42gc-7vw4 | CVSS: 5.3",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "low",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-79qm-7rj5-m7r9",
            "title": "GHSA-79qm-7rj5-m7r9 \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-71849, GHSA-79qm-7rj5-m7r9 | CVSS: 3.7",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-8j4g-w8fx-2239",
            "title": "GHSA-8j4g-w8fx-2239 \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-69207, GHSA-8j4g-w8fx-2239 | CVSS: 5.3",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-f23p-vx2j-j53r",
            "title": "GHSA-f23p-vx2j-j53r \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-71850, GHSA-f23p-vx2j-j53r | CVSS: 4.8",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-hvrm-45r6-mjfj",
            "title": "GHSA-hvrm-45r6-mjfj \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-59896, GHSA-hvrm-45r6-mjfj | CVSS: 6.5",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-w62v-xxxg-mg59",
            "title": "GHSA-w62v-xxxg-mg59 \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-59895, GHSA-w62v-xxxg-mg59 | CVSS: 6.1",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-xgm2-5f3f-mvvc",
            "title": "GHSA-xgm2-5f3f-mvvc \u2014 npm hono@4.12.25",
            "description": "aliases: CVE-2026-59897, GHSA-xgm2-5f3f-mvvc | CVSS: 4.8",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-22jq-vg5j-6vgg",
            "title": "GHSA-22jq-vg5j-6vgg \u2014 npm ip-address@10.2.0",
            "description": "aliases: CVE-2026-54272, GHSA-22jq-vg5j-6vgg | CVSS: 6.9",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "medium",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-4xrf-jv44-h6hh",
            "title": "GHSA-4xrf-jv44-h6hh \u2014 npm ip-address@10.2.0",
            "description": "aliases: CVE-2026-69198, GHSA-4xrf-jv44-h6hh | CVSS: 6.9",
            "remediation": null
          },
          {
            "tool_name": "osv-scanner",
            "severity": "high",
            "category": "npm",
            "file_path": "/repo/pnpm-lock.yaml",
            "line_number": null,
            "rule_identifier": "GHSA-mwp4-54f8-5fhr",
            "title": "GHSA-mwp4-54f8-5fhr \u2014 npm ip-address@10.2.0",
            "description": "aliases: CVE-2026-69192, GHSA-mwp4-54f8-5fhr | CVSS: 7.7",
            "remediation": null
          }
        ],
        "execution_duration_seconds": 6.83172498102067,
        "status": "complete",
        "examined": {
          "unit": "manifests",
          "count": 1
        },
        "metadata": {
          "source": "github-releases",
          "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
          "report_type": "osv-vulnerability",
          "ecosystems_seen": [
            "npm"
          ],
          "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
          "severity_counts": {
            "low": 1,
            "high": 7,
            "medium": 9,
            "critical": 0,
            "informational": 0
          },
          "manifests_scanned": [
            "/repo/pnpm-lock.yaml"
          ],
          "finding_id_aliases": {
            "GHSA-22jq-vg5j-6vgg": [
              "CVE-2026-54272"
            ],
            "GHSA-3jxr-9vmj-r5cp": [
              "CVE-2026-13149"
            ],
            "GHSA-4c8g-83qw-93j6": [
              "CVE-2026-13676"
            ],
            "GHSA-4xrf-jv44-h6hh": [
              "CVE-2026-69198"
            ],
            "GHSA-54fx-42gc-7vw4": [
              "CVE-2026-71848"
            ],
            "GHSA-79qm-7rj5-m7r9": [
              "CVE-2026-71849"
            ],
            "GHSA-7p8r-x3mc-p8w7": [
              "CVE-2026-18446"
            ],
            "GHSA-8j4g-w8fx-2239": [
              "CVE-2026-69207"
            ],
            "GHSA-f23p-vx2j-j53r": [
              "CVE-2026-71850"
            ],
            "GHSA-hvrm-45r6-mjfj": [
              "CVE-2026-59896"
            ],
            "GHSA-mh99-v99m-4gvg": [
              "CVE-2026-14257"
            ],
            "GHSA-mwp4-54f8-5fhr": [
              "CVE-2026-69192"
            ],
            "GHSA-rgw5-rvv9-x895": [
              "CVE-2026-69152"
            ],
            "GHSA-v2hh-gcrm-f6hx": [
              "CVE-2026-16221"
            ],
            "GHSA-w62v-xxxg-mg59": [
              "CVE-2026-59895"
            ],
            "GHSA-xgm2-5f3f-mvvc": [
              "CVE-2026-59897"
            ]
          },
          "cross_scanner_correlation": {
            "only_osv": [
              "GHSA-3jxr-9vmj-r5cp",
              "GHSA-mh99-v99m-4gvg",
              "GHSA-rgw5-rvv9-x895"
            ],
            "only_trivy": [],
            "intersection_ids": [
              "CVE-2026-13676",
              "CVE-2026-16221",
              "CVE-2026-18446",
              "CVE-2026-54272",
              "CVE-2026-59895",
              "CVE-2026-59896",
              "CVE-2026-59897",
              "CVE-2026-69192",
              "CVE-2026-69198",
              "CVE-2026-69207",
              "CVE-2026-71848",
              "CVE-2026-71849",
              "CVE-2026-71850",
              "GHSA-frvp-7c67-39w9"
            ]
          }
        },
        "display_score": 0.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "trivy_image",
        "scanner_version": "0.71.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 3.597000613808632e-05,
        "status": "not_applicable",
        "examined": {
          "unit": "image_targets",
          "count": 0
        },
        "metadata": {
          "reason": "no OCI image acquired for this artifact"
        },
        "display_score": null,
        "display_badge": "not_applicable"
      },
      {
        "scanner_name": "govulncheck",
        "scanner_version": "v1.6.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 0.06348048703512177,
        "status": "not_applicable",
        "examined": {
          "unit": "modules",
          "count": 0
        },
        "metadata": {
          "source": "go-module-proxy",
          "source_url": "https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck",
          "report_type": "go-reachability",
          "vendor_mode": false,
          "go_mod_present": false,
          "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install golang.org/x/vuln/cmd/govulncheck@v1.6.0  # golang.org/x/vuln v1.6.0 h1:FeMO9Rm/HwyduOztbvKcOw+zvDEPr4I4aQNSfevFcKY=",
          "offline_db_path": "/opt/govulncheck-db",
          "environment_note": "govulncheck found no go.mod, so this tree declares no Go module and no Go dependencies; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute"
        },
        "display_score": null,
        "display_badge": "not_applicable"
      }
    ]
  },
  "report": {
    "report_id": "92778812-8757-47c2-bf4c-eb8babc28116",
    "format": "json",
    "generated_at": "2026-08-12T17:00:13.458550+00:00",
    "scanner_filter": null,
    "signature": null
  }
}